New HollowGraph Malware Hijacks Microsoft 365 Calendars for Covert C2

A sophisticated new malware called HollowGraph is using Microsoft 365 calendars as a covert command and control channel to target Israeli organizations. Researchers believe the malware is linked to a well-resourced adversary with technical similarities to the Iranian-nexus group Lyceum.
Why it matters
This highlights an evolving cybersecurity threat where attackers exploit trusted enterprise software to bypass traditional network security.
A newly identified Windows malware sample abuses Microsoft Graph API to transform a compromised Microsoft 365 calendar into a covert two-way command and control (C2) channel.
Researchers at Group-IB dubbed the highly sophisticated malware sample HollowGraph and attributed it, with high confidence, to the Cavern backdoor framework.
Analysis by Group-IB found that the HollowGraph attack is highly targeted and focuses on Israeli entities. This is because the compromised mailbox identified was associated with an Israeli organization.
In addition, the malware files uploaded were from Israel and files associated with the broader Cavern framework were also uploaded from Israel.
Group-IB said it identified 12 systems infected with the HollowGraph malware and earliest observed communication between a victim and attacker occurred on June 3, 2026. The most recent example was identified on July 9.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in